[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] New email worm / virus.



IF YOU DECIDE TO FORWARD THIS, DO NOT EDIT IT, ADD COMMENTS, 
OR REMOVE ANY TEXT.

Heads up!

I've been getting lots of copies of an email containing a vbscript worm
/ virus.  (Which is it?).  McAfee were not aware of it when we contacted 
them, although I suspect that it's an old one with a new subject line.

At any rate, it got through a Mimesweeper installation, which goes to show 
that scanning is no substitute for not having a secure system in the 
first place.

The email arrives as subject line "ILOVEYOU" and contains the line
 "kindly check the attached LOVELETTER coming from me." and then a
script, which if executed does all sorts of nasty things.

It appears to rely on the ability to download a file called 
WIN-BUGSFIX.exe from a website, which is now no longer there, 
so it should be short-lived.  But there may be variants using
other websites.

This email was originally written on May 4th 2000, by d.latter@xxxxxxxx
You may contact me, or p.clarke@xxxxxxx if you wish to verify it.

Here are the first few lines of the script:

 rem  barok -loveletter(vbe) <i hate go to school>
 rem                     by: spyder  /  ispyder@xxxxxxxx  /  @GRAMMERSoft Group 
/  =
 Manila,Philippines
 On Error Resume Next
 dim fso,dirsystem,dirwin,dirtemp,eq,ctr,file,vbscopy,dow
 eq=3D""
 ctr=3D0
 Set fso =3D CreateObject("Scripting.FileSystemObject")
 set file =3D fso.OpenTextFile(WScript.ScriptFullname,1)
 vbscopy=3Dfile.ReadAll
 main()

Remember, if you receive an email saying "send this to everyone 
you know", DON'T!  If you must, check with a system administrator.
Or check at www.symantec.com, or www.mcafee.com, or do a websearch
on "hoax virus".

Dom Latter & Paul Clarke, @ Storage Area Networks Limited.